Close Menu
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
What's Hot

Initial D, MF Ghost Manga Get Subaru and Subaru Sequel in July – News

June 7, 2025

Yamishibai: Japanese Ghost Stories Anime Gets 15th Season on July 13 – News

June 7, 2025

Egos, powers and reforms – Aminul’s challenge with Bangladesh cricket

June 7, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
Home » New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users
Cybersecurity

New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users

HarishBy HarishJune 6, 2025No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
Share
Facebook Twitter Pinterest Reddit WhatsApp Email


New Atomic macOS Stealer Campaign

Cybersecurity researchers are alerting to a new malware campaign that employs the ClickFix social engineering tactic to trick users into downloading an information stealer malware known as Atomic macOS Stealer (AMOS) on Apple macOS systems.

The campaign, according to CloudSEK, has been found to leverage typosquat domains mimicking U.S.-based telecom provider Spectrum.

“macOS users are served a malicious shell script designed to steal system passwords and download an AMOS variant for further exploitation,” security researcher Koushik Pal said in a report published this week. “The script uses native macOS commands to harvest credentials, bypass security mechanisms, and execute malicious binaries.”

It’s believed that the activity is the work of Russian-speaking cybercriminals owing to the presence of Russian language comments in the malware’s source code.

Cybersecurity

The starting point of the attack is a web page that impersonates Spectrum (“panel-spectrum[.]net” or “spectrum-ticket[.]net”). Visitors to the sites in question are served a message that instructs them to complete a hCaptcha verification check to in order to “review the security” of their connection before proceeding further.

However, when the user clicks the “I am human” checkbox for evaluation, they are displayed an error message stating “CAPTCHA verification failed,” urging them to click a button to go ahead with an “Alternative Verification.”

Doing so causes a command to be copied to the users’ clipboard and the victim is shown a set of instructions depending on their operating system. While they are guided to run a PowerShell command on Windows by opening the Windows Run dialog, it’s substituted by a shell script that’s executed by launching the Terminal app on macOS.

The shell script, for its part, prompts users to enter their system password and downloads a next-stage payload, in this case, a known stealer called Atomic Stealer.

“Poorly implemented logic in the delivery sites, such as mismatched instructions across platforms, points to hastily assembled infrastructure,” Pal said.

“The delivery pages in question for this AMOS variant campaign contained inaccuracies in both its programming and front-end logic. For Linux user agents, a PowerShell command was copied. Furthermore, the instruction ‘Press & hold the Windows Key + R’ was displayed to both Windows and Mac users.”

The disclosure comes amid a surge in campaigns using the ClickFix tactic to deliver a wide range of malware families over the past year.

“Actors carrying out these targeted attacks typically utilize similar techniques, tools, and procedures (TTPs) to gain initial access,” Darktrace said. “These include spear phishing attacks, drive-by compromises, or exploiting trust in familiar online platforms, such as GitHub, to deliver malicious payloads.”

The links distributed using these vectors typically redirect the end user to a malicious URL that displays a fake CAPTCHA verification check and completes it in an attempt to deceive users into thinking that they are carrying out something innocuous, when, in reality, they are guided to execute malicious commands to fix a non-existent issue.

The end result of this effective social engineering method is that users end up compromising their own systems, effectively bypassing security controls.

In one April 2025 incident analyzed by Darktrace, unknown threat actors were found to utilize ClickFix as an attack vector to download nondescript payloads to burrow deeper into the target environment, conduct lateral movement, send system-related information to an external server via an HTTP POST request, and ultimately exfiltrate data.

“ClickFix baiting is a widely used tactic in which threat actors exploit human error to bypass security defenses,” Darktrace said. “By tricking endpoint users into performing seemingly harmless, everyday actions, attackers gain initial access to systems where they can access and exfiltrate sensitive data.”

Cybersecurity

Other ClickFix attacks have employed phony versions of other popular CAPTCHA services like Google reCAPTCHA and Cloudflare Turnstile for malware delivery under the guise of routine security checks.

These fake pages are “pixel-perfect copies” of their legitimate counterparts, sometimes even injected into real-but-hacked websites to trick unsuspecting users. Stealers such as Lumma and StealC, as well as full-fledged remote access trojans (RATs) like NetSupport RAT are some of the payloads distributed via bogus Turnstile pages.

“Modern internet users are inundated with spam checks, CAPTCHAs, and security prompts on websites, and they’ve been conditioned to click through these as quickly as possible,” SlashNext’s Daniel Kelley said. “Attackers exploit this ‘verification fatigue,’ knowing that many users will comply with whatever steps are presented if it looks routine.”

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
Previous ArticleBandai Namco Announces New Dragon Ball Gekishin Squadra Game – News
Next Article Humans provide necessary ‘checks and balances’ for AI, says Lattice CEO
Harish
  • Website
  • X (Twitter)

Related Posts

Empower Users and Protect Against GenAI Data Loss

June 6, 2025

Microsoft Helps CBI Dismantle Indian Call Centers Behind Japanese Tech Support Scam

June 6, 2025

Why More Security Leaders Are Selecting AEV

June 6, 2025

New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack

June 6, 2025

Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials

June 5, 2025

Researchers Detail Bitter APT’s Evolving Tactics as Its Geographic Scope Expands

June 5, 2025
Add A Comment
Leave A Reply Cancel Reply

Our Picks

Initial D, MF Ghost Manga Get Subaru and Subaru Sequel in July – News

June 7, 2025

Yamishibai: Japanese Ghost Stories Anime Gets 15th Season on July 13 – News

June 7, 2025

Egos, powers and reforms – Aminul’s challenge with Bangladesh cricket

June 7, 2025

Building More Scalable GenAI Applications for Startups and Developers

June 7, 2025
Don't Miss
Blockchain

Bitcoin market of 2025 driven by stablecoin regulation: Finance Redefined

June 6, 20256 Mins Read

Despite a week of price consolidation for Bitcoin (BTC), emerging digital asset legislation may provide…

How to Earn Passive Income with Peer-to-Peer Lending

June 6, 2025

Mass data deletion by governments is accelerating.

June 6, 2025

Cointelegraph Bitcoin & Ethereum Blockchain News

June 6, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Luminari, your go-to hub for mastering modern tech and staying ahead in the digital world.

At Luminari, we’re passionate about breaking down complex technologies and delivering insights that matter. Whether you’re a developer, tech enthusiast, job seeker, or lifelong learner, our mission is to equip you with the tools and knowledge you need to thrive in today’s fast-moving tech landscape.

Our Picks

Building More Scalable GenAI Applications for Startups and Developers

June 7, 2025

2025 will be a ‘pivotal year’ for Meta’s augmented and virtual reality, says CTO

June 6, 2025

The case for AI co-founders, from less equity dilution to an infinite memory

June 6, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 luminari. Designed by luminari.

Type above and press Enter to search. Press Esc to cancel.